TECHNICAL FIELD OF THE INVENTION
[0001] The present application relates to an authentication system, and in particular, to
a photonic authentication system for modulating an identification code into a light
signal and authenticating the light signal.
BACKGROUND OF THE INVENTION
[0002] Currently, a common authentication system generally includes a receive terminal and
a transmit terminal, where rights are set for the transmit terminal, and the receive
terminal receives authentication information transmitted by the transmit terminal,
authenticates the transmit terminal, and after the authentication is passed, may allow
the transmit terminal to perform an operation on the receive terminal. For example,
in an access control system, all related technical solutions use a contactless proximity
card such as an RFID (radio frequency) card or an IC card to perform a security authentication.
The access control system using a proximity card for working is a proximity card access
control system. The proximity card access control system transfers information to
a card reader by using a proximity card. The card reader then transfers the proximity
card information to an access controller. The access controller determines whether
the card is a valid card, and transmits a determining result to the card reader. If
the card is a valid card, the card reader gives out a "beep", which represents that
the card is a valid card, and meanwhile, the access controller unlocks an electric
lock to open a door. When the card is an invalid card, the card reader does not perform
any action and does not give out any sound, and the electric lock does not make any
response. However, with continuous development of cracking technologies, currently,
all RFID cards can be easily cracked, card information is replicated, and therefore
a severe security problem exists. It is more difficult to crack an IC card. However,
a method capable of cracking is also available currently, and the security problem
still exists.
[0003] In addition to the foregoing proximity card access control system, some systems that
transmit signals by using visible light begin to be applied. An access control system
of this type mainly performs wireless information transmission by means of visible
light. The system performs communication by flashing an LED light source at a high
frequency, and generally includes a transmitter and a receiver. At the transmitter,
an LED emits light and flashes at a frequency invisible to a human's eye, where in
a specific period of time, presence of light indicates a binary signal "1", and absence
of light indicates a binary signal "0". At the receiver (equivalent to a card reader),
the light signal is converted into an electrical signal by using a photoelectric conversion
component such as a photoresistor, and decoding is performed to obtain a corresponding
card signal. Then the card signal is transferred to an access controller, and the
access controller determines whether the transmitter has a right to open a door, and
thereby determines whether to unlock the door. The foregoing solution in which visible
light is used to perform short-range communication to transmit information of a transmitter
is also feasible. However, because visible light can be emitted by only the triggered
transmitter, and the light signal is transmitted by fast flashing, the light signal
may be photographed by a high-speed camera, and visible light flashing information
is obtained, and then transmitted information content is obtained by analyzing changes
of flashing. Even if the information content is encrypted by the transmitter, the
photographed content may also be illegally replicated, and a same transmit apparatus
is made for transmitting the replicated light signal, and thereby the door of the
photonic access control system can also be unlocked. Therefore, a security risk also
exists.
SUMMARY
[0005] The invention is defined in the independent claims. Additional features of the invention
are provided in the dependent claims. The embodiments and/or examples disclosed in
the following description which are not covered by the appended claims are considered
as not being part of the present invention.
[0006] In the present application, an information transmit module and a light receive module
are disposed in a receiver of an authentication system, and an information receive
module and a light transmit module are disposed in a transmitter. The receiver externally
propagates, by using the information transmit module, an identification code information
set corresponding to the receiver. Only when the transmitter enters a propagation
range of the receiver, can the transmitter receive the identification code information
transmitted by the receiver. The transmitter firstly performs a first right authentication
on whether the transmitter has operation rights. The transmitter allows itself to
transmit a light signal of a unique identification code of the transmitter only when
the transmitter has operation rights, that is, only when the transmitter has rights
to operate the receiver, thereby reducing a security risk caused by uncontrolled transmission
of the light signal of the identification code of the transmitter by the transmitter.
After the transmitter transmits the light signal of the identification code of the
transmitter, the receiver performs a second right authentication on the received light
signal. In this way, security of the authentication system is further improved.
BRIEF DESCRIPTION OF DRAWINGS
[0007]
FIG. 1 is a schematic structural diagram of an embodiment of the present application;
FIG. 2a is a schematic structural diagram of an access control system according to
an embodiment of the present application;
FIG. 2b is a schematic structural diagram of an access control system according to
another embodiment of the present application;
FIG. 3 is a schematic structural diagram of a transmitter according to still another
embodiment of the present application;
FIG. 4 is a flowchart of a first right authentication in an access control system
according to an embodiment of the present application; and
FIG. 5 is a flowchart of a second right authentication in an access control system
according to an embodiment of the present application.
DESCRIPTION OF EMBODIMENTS
[0008] The following further describes the present invention by using embodiments with reference
to accompanying drawings.
[0009] An authentication system in the present application may be applied to an access control
system, or may be applied to a system that requires authorization such as a consumption
management system, a transaction system, or a metro system, where the consumption
management system may be a system that requires authorization of a voucher, ticket
management, a discount coupon, or a membership card, or the like. As shown in FIG.
1, the authentication system includes a transmit terminal, a receive terminal, and
a management server 50, where the transmit terminal includes a transmitter 10, the
receive terminal includes a receiver 20 and a controller 30. The controller 30 is
communicatively connected to the receiver 20 and the management server 50 respectively,
where the management server 50 stores an identification code information set corresponding
to each receiver. The receiver 20 includes an information transmit module 21 and a
light receive module 22, where the information transmit module 21 and the light receive
module 22 are communicatively connected to the controller 30 respectively. The transmitter
10 includes a processor 11, an information receive module 12, and a light transmit
module 13, where the processor 11 is connected to the information receive module 12
and the light transmit module 13 respectively. A working process of the authentication
system is: the receiver 20 externally propagates, by using the information transmit
module 21, acquired identification code information corresponding to the receiver;
after receiving, by using the information receive module 12, an identification code
information set transmitted by the receiver, the transmitter 10 transfers the identification
code information set to the processor 11; the processor 11 performs, according to
the received identification code information set, a first right authentication on
whether the transmitter has operation rights, and determines, according to an authentication
result, whether to allow converting transmitter information of the transmitter into
a light signal for transmission by using the light transmit module 13, where the transmitter
information includes at least a unique identification code of the transmitter; and
after the receive terminal receives the transmitter information that is transmitted
by the transmitter in a light signal form by using the light receive module 22, the
receive terminal transfers the transmitter information to the controller 30; the controller
30 performs a second right authentication on the transmitter information, and performs
an action according to an authentication result. For example, according to the authentication
result, the controller determines whether to output a corresponding control signal.
According to different applications of the authentication system, functions of control
signals output by the controller also vary. For example, when the authentication system
is an access control system, a consumption management system, or a metro system, the
authentication system further includes an access control switch apparatus configured
to switch between an on state and an off state, the controller is further communicatively
connected to the access control switch apparatus, and after performing the second
right authentication on the transmitter information, the controller determines, according
to the authentication result, whether to output a control signal to the access control
switch apparatus, where a function of the control signal may be to control turn-on
of the access control switch apparatus of the authentication system (for example,
control a controllable lock to unlock or control a gate to open). When the authentication
system is a transaction system, the transaction system further includes a cash register,
a POS machine, or a computer, the controller is further communicatively connected
to the cash register or the POS machine, and after performing the second right authentication
on the transmitter information, the controller determines, according to the authentication
result, whether to output a cash control signal to the cash register, the POS machine,
or the computer, where a function of the control signal is to control the cash register,
the POS machine, or the computer to receive money according to a predetermined manner.
Embodiment 1
[0010] In this embodiment, an authentication system is an access control system, which is
used as an example for description, where a management server is an access control
management server, and a controller is an access controller.
[0011] Referring to FIG. 2a, an access control system 100 includes a transmit terminal and
a receive terminal. In this embodiment, the transmit terminal is a transmitter 110,
and the receive terminal includes a receiver 120 and an access controller 130. In
order to control a door, the access control system 100 further includes an access
control switch apparatus configured to switch between an on state and an off state.
In this embodiment, the access control switch apparatus is a controllable lock 140;
in other embodiments, the access control switch apparatus may be a gate. For ease
of management of the access control system, the access control system 100 further
includes an access control management server 150, where the access control management
server 150 stores unique identification code information of all transmitters corresponding
to each receiver. The unique identification code information of all the transmitters
corresponding to each receiver may be the same or different. The access controller
130 is communicatively connected to the receiver 120, the access control management
server 150, and the controllable lock 140 respectively, where the communication connection
manner may be a wired connection or a wireless communication connection. For ease
of displaying information, the access control system 100 further includes a display
160, where the display 160 is connected to the access controller 130 and displays
information output by the access controller 130. In this embodiment, the access controller
130 may acquire information from the access control management server 150; the access
controller 130 may also transmit data to the receiver 120 or control the receiver
120 to execute an instruction; the access controller 130 may further control the controllable
lock 140 to change the current state, for example, control the controllable lock 140
to change to an unlocked state or a locked state. The controllable lock 140 may be
an electric lock whose unlocking or locking is controlled by an electrical signal,
or may be a lock controlled in other manners.
[0012] In this embodiment, the transmitter 110 may convert its unique identification code
into a light signal for transmission. When the transmitter 110 transmits a light signal
to the receiver 120, the receiver 120 converts the received light signal into an electrical
signal, and outputs the electrical signal to the access controller 130; the access
controller 130 performs an authentication according to the electrical signal including
the identification code of the transmitter 110, determines whether the transmitter
110 has a right to open a controlled door controlled by the receiver 120, and if the
transmitter 110 has the right, outputs a control signal to control unlocking of the
controllable lock.
[0013] In this embodiment, the receiver 120 includes a first radio frequency module 121
used as an information transmit module, and a light receive module 122, where the
first radio frequency module 121 and the light receive module 122 are communicatively
connected to the access controller 130. The first radio frequency module 121 may convert
information transmitted by the access controller 130 into a radio frequency signal
for transmission. Certainly, in other embodiments, the first radio frequency module
121 may further receive a radio frequency signal, and transmit the radio frequency
signal to the access controller 130 after performing corresponding processing. The
light receive module 122 may receive a light signal, and convert the light signal
into an electrical signal for outputting to the access controller 130. The transmitter
110 includes a processor 111, a second radio frequency module 112 used as an information
receive module, and a light transmit module 113, where the processor 111 is connected
to the second radio frequency module 112 and the light transmit module 113 respectively.
The second radio frequency module 112 may receive a radio frequency signal, and transmit
the radio frequency signal to the processor 111 after performing corresponding processing.
Certainly, in other embodiments, the second radio frequency module 112 may further
externally transmit a radio frequency signal. The light transmit module 113 may convert
the electrical signal output by the processor 111 into a light signal for transmission.
[0014] In this embodiment, the access controller 130 periodically or randomly obtains an
identification code information set corresponding to the receiver 120 from the access
control management server 150, where the identification code information set includes
unique identification codes of all transmitters 110 corresponding to (that is, having
a right to open a door controlled by the receiver) the receiver, and transmits the
identification code information set to the receiver 120; after receiving the identification
code information set from the access controller 130, the first radio frequency module
121 of the receiver 120 performs processing as required, for example, encrypts the
identification code information set, and after processing, externally propagates the
identification code information set continuously or intermittently in a radio frequency
manner in a range (for example, in a rage of several meters).
[0015] When the transmitter 110 enters the range, the second radio frequency module 112
may receive the radio frequency signal transmitted by the first radio frequency module
121. The second radio frequency module 112 performs processing on the identification
code information set transmitted by the first radio frequency module 121 as required,
for example, performs decryption. After the processing, the second radio frequency
module 112 sends the identification code information set to the processor 111. The
processor 111 performs first right authentication on whether the transmitter has a
right to operate the controllable lock controlled by the receiver according to the
received identification code information set, and controls an enable state of the
light transmit module 113 according to an authentication result. And when the authentication
is passed, the light transmit module 113 is controlled to be in a state in which a
light signal can be transmitted, or when the authentication is not passed, the light
transmit module 113 is controlled to be in a state in which a light signal cannot
be transmitted. In this embodiment, a specific authentication scheme is: the processor
111 compares the unique identification code of the transmitter 110 with the received
identification code information set, then determines whether to allow converting transmitter
information of the transmitter into a light signal for transmission, according to
a comparison result, where the transmitter information includes at least the unique
identification code of the transmit terminal And if the received identification code
information set includes an identification code that is the same as the unique identification
code of the transmitter, it considers that the transmitter has a right to open the
controlled door, and controls the light transmit module 113 to switch to a working
state that allows converting the transmitter information of the transmitter into a
light signal for transmission. After switching to the working state that allows work,
the light transmit module 113 may convert the transmitter information of the transmitter
into a light signal for transmission, or otherwise, control the light transmit module
113 to be in a working state that forbids converting transmitter information of the
transmitter into a light signal for transmission or to maintain an original state.
In other embodiment, the identification code information set may be other information,
and different authentication methods may be used for the first right authentication
according to different identification code information sets. For example, the identification
code information set includes identity information of the receive terminal, the transmitter
110 stores identity information of all receive terminals that the transmitter has
rights to operate. And a method of the first right authentication may further be:
comparing the received identification code information set with the identity information
of all the receive terminals that the transmitter 110 has the rights to operate which
is stored by the transmitter 110 by the processor 111. If the identity information
of all the receive terminals that the transmitter 110 has the rights to operate which
is stored by the transmitter 110 includes the identification code information set,
it is considered that the transmitter has a right to open the controlled door, and
the light transmit module 113 is controlled to switch to a working state that allows
converting the transmitter information of the transmitter into a light signal for
transmission, or otherwise, the light transmit module 113 is controlled to be in a
working state that forbids converting the transmitter information of the transmitter
into a light signal for transmission or to maintain an original state, where the transmitter
information includes at least the unique identification code of the transmitter.
[0016] The light receive module 122 of the receiver 120 performs photoelectric conversion
after receiving a light signal from the light transmit module 113, and outputs an
electrical signal of the transmitter information to the access controller 130. The
access controller 130 performs a second right authentication on the transmitter information
after receiving the transmitter information, and determines, according to an authentication
result, whether to output a control signal for controlling unlocking of the controllable
lock. In this embodiment, an authentication method may be, for example, comparing
the transmitter information with the identification code information set, and if the
identification code information set includes the transmitter information, outputting
a first control signal to the controllable lock to control unlocking of the controllable
lock. In another embodiment, the authentication method may be further including right
information of the transmitter for each controlled door into the transmitter information;
the access controller 130 determines, according to the right information after receiving
the transmitter information, whether the transmitter has a right to open the controlled
door controlled by the receiver, and if yes, outputs a control signal to control unlocking
of the controllable lock.
[0017] As shown in a schematic structural diagram of an access control system 200 in FIG.
2b, when it is necessary to perform encryption and decryption processing on an identification
code, a first decryption module 115 and a first encryption module 114 may be added
to a transmitter 110. The first decryption module 115 is connected between a processor
111 and a second radio frequency module 112, and decrypts an identification code information
set received by the second radio frequency module 112, and outputs the decrypted identification
code information set to the processor 111; the first encryption module 114 is configured
to encrypt transmitter information of the transmitter, and the first encryption module
114 is connected between the processor and a light transmit module. A second encryption
module 123 and a second decryption module 124 may be added to a receiver 120. The
second encryption module 123 is connected between an access controller 130 and a first
radio frequency module 121, and encrypts the identification code information set received
from the access controller 130 and outputs the encrypted identification code information
set to the first radio frequency module 121; the second decryption module 124 is connected
between a light receive module 122 and the access controller 130, and performs signal
decryption after receiving a signal obtained through photoelectric conversion and
output by the light receive module 122, and then outputs the signal to the access
controller 130.
[0018] In an actual use process, a transmitter is generally carried by a user, and a receiver
is generally installed beside a controlled door. A controllable lock is installed
on the controlled door. The controllable lock controls, by switching a state of the
controllable lock, whether to allow or forbid the controllable door to open. An access
control management server may be disposed in a secure place, for example, an administrator's
office or an equipment room. An access controller performs data communication with
the access control management server by using a wired communication network or a wireless
communication network. A working process of this embodiment is as follows:
A receiver periodically obtains unique identification codes of all transmitters that
currently have a right to open a door corresponding to the receiver from a database
of an access control management server by using an access controller. Then all the
identification codes are encrypted, and are propagated in a small range of several
meters in a radio frequency manner by using a radio frequency transmit module of the
receiver.
2. When a transmitter approaches the receiver near the door, the transmitter enters
a radio frequency propagation range, and starts to receive a signal propagated in
the radio frequency manner.
3. The transmitter decrypts the received signal propagated in the radio frequency
manner, and checks whether a code that is the same as a unique identification code
of the transmitter exists in the decrypted signal. If a code that is the same as the
unique identification code of the transmitter exists, it indicates that the transmitter
has the right to open the door corresponding to the receiver. When a user presses
a button, a visible light transmit module is started, transmitter information is dynamically
encrypted, and the transmitter information is transmitted in a visible light form
by using the visible light transmit module.
4. When the receiver receives the visible light signal, the receiver performs photoelectric
conversion by using a visible light receive module, obtains the transmitter information
that is encrypted by using a dynamic key, and then decrypts the signal content by
using a dynamic key that is generated according to the same previous algorithm, and
obtains the original transmitter information. After the transmitter information is
obtained, the receiver sends the transmitter information to the access controller.
The access controller determines rights of the transmitter for a second time to determine
whether the transmitter is legal. If the transmitter is legal, a controllable lock
is unlocked. If the transmitter is illegal, the controllable lock is not unlocked,
and a prompt indicating that the transmitter is illegal is provided.
5. After the signal propagated in the radio frequency manner is decrypted, if the
transmitter does not find a code correspond with the unique code of the device, it
indicates that the transmitter does not have the right to unlock the door corresponding
to the current receiver. Then even if the user presses a start button in the propagation
range of the receiver, the transmitter does not start the visible light transmit module,
and therefore no visible light signal is transmitted, and the access controller does
not perform any action.
[0019] Apparently, in the technical solution of this embodiment, only when a transmitter
determines that a received identification code information set includes an identification
code that is the same as a unique identification code of the transmitter, that is,
only when the transmitter approaches a controlled door and has a right to open the
controlled door, can a user operate the transmitter, so that the transmitter transmits
a light signal converted from the identification code. If the two conditions are not
satisfied, the transmitter does not transmit any light signal converted from the identification
code, thereby it reduces a security risk caused by replication by using a high-speed
camera by other people. After the transmitter transmits a light signal, after a receive
terminal receives the light signal, the receive terminal performs a right authentication
once again on the transmitter (namely, an emitter) that transmits the light signal.
The transmitter is allowed to open the controlled door only when the two authentications
are both passed. Therefore, in this embodiment, two authentications are performed
on whether the transmitter has the right to open the controlled door, and thereby
security of the access control system is further improved.
[0020] In this embodiment, an information transmit module obtains an identification code
information set from an access control management server by using an access controller.
In other embodiments, an information transmit module may further obtain an identification
code information set from an access control management server directly.
[0021] In other embodiments, an information transmit module of a receiver may further use
other wireless manners to transmit information. For example, the information transmit
module may be a Wi-Fi transmit module, an infrared transmit module, a Bluetooth transmit
module, or a low-frequency electromagnetic wave transmit module; correspondingly,
an information receive module of a transmitter may also be a Wi-Fi receive module,
an infrared receive module, a Bluetooth receive module, or a low-frequency electromagnetic
wave receive module.
Embodiment 2
[0022] Referring to FIG. 3, different from the foregoing embodiment, a transmitter 110 further
includes a power supply 115, a trigger switch 116, and a control switch 117, where
the trigger switch 116 and the control switch 117 are wired in series between the
power supply 115 and a light transmit module 113. A control end of the control switch
117 is coupled to a processor 111, and the control switch switches between an on state
and an off state according to a control signal output by the processor 111. When the
processor 111 determines that a received identification code information set includes
an identification code that is the same as a unique identification code of the transmitter,
the processor 111 controls the control switch 117 to be on; or otherwise, and controls
the control switch 117 to be off. The trigger switch 116 is configured to switch between
an on state and an off state in response to an operation of a user. Therefore, only
when both the trigger switch 116 and the control switch 117 are in the on state, can
the light transmit module 113 connect the power supply for working.
[0023] In some cases, a user passes through a propagation range of a receiver, but does
not need to open a controlled door. Therefore, the user does not need to trigger the
transmitter to transmit a light signal. To prevent the control switch 117 from always
being in the on state in this case, a timer may be started immediately after the processor
111 determines that the received identification code information set includes the
identification code that is the same as the unique identification code of the transmitter.
After the timer expires, the control switch 117 is controlled to be off.
[0024] Certainly, in other embodiments, a person skilled in the art may also use other manners,
based on the content disclosed by the present application, to control the light transmit
module 113 to switch between a state of allowing work and a state of forbidding work.
For example, a switch is disposed on a transmission path on which the processor 111
transmits the identification code of the transmitter to the light transmit module
113, where the state of the switch is controlled by the processor 111. Likewise, transmission
of the identification code by the light transmit module 113 may also be controlled.
[0025] To enhance the security of an access control system and to enable the transmitter
110 to convert, only in a controllable state, its unique identification code into
a light signal for transmission, when the access control system performs a right authentication
in this embodiment, steps of transmitting a light signal and performing timing control
based on a user trigger are further added on a basis of a second authentication. At
a transmit terminal, firstly a transmitter performs a first authentication on whether
the transmitter has a right to open a controlled door, where a process is shown in
FIG. 4, and the process includes the following steps:
Step 401: A receiver externally propagates an acquired identification code information
set corresponding to the receiver continuously or intermittently, where the identification
code information set includes unique identification code information of all transmitters
corresponding to the receiver.
Step 402: A transmitter authenticates its own rights. After receiving the identification
code information set transmitted by the receiver, the transmitter compares a unique
identification code of the transmit terminal with the received identification code
information set, passes the right authentication if the received identification code
information set includes an identification code same as the unique identification
code of the transmit terminal, and performs step 403; or otherwise, performs step
404 to forbid converting transmitter information of the transmitter into a light signal
for transmission by using a light transmit module, or may maintain an original state.
Step 403: The transmitter allows converting the transmitter information of the transmitter
into a light signal for transmission by using the light transmit module, and at the
same time, starts a timer.
Step 405: The transmitter detects whether a user inputs a light transmission trigger
signal, and if yes, performs step 406, or otherwise performs step 407.
Step 406: The transmitter controls, according to the light transmission trigger signal,
the light transmit module to convert the transmitter information of the transmit terminal
into a light signal for transmission.
Step 407: The transmitter determines whether the timer expires, and if the timer expires,
performs step 404, or otherwise, continues to perform step 405.
[0026] By controlling a timer in this embodiment, the transmitter is forbidden to transmit
a light signal again after a set time expires after the transmitter passes its own
authentication; the transmitter is allowed to transmit a light again after the transmitter
passes its own authentication again, where a validity period is specified for authenticating
the transmitter. In this way, security of the authentication system is further improved.
[0027] At a receive terminal, a second authentication is performed on whether a transmitter
has a right to open a controlled door. A process executed by the receive terminal
is shown in FIG. 5, and includes the following steps:
Step 501: A receiver detects a light signal by using a light receive module; when
receiving transmitter information that is transmitted by a transmitter in a light
signal form, performs photoelectric conversion on the transmitter information, and
then sends the transmitter information to an access controller.
Step 502: The access controller performs a right authentication on the transmitter
information, and if the authentication is passed, performs step 503, or otherwise
performs step 504. That the access controller performs a right authentication on the
transmitter information includes: comparing the transmitter information with an identification
code information set stored by the access controller, and outputting a control signal
for controlling unlocking of a controllable lock when determining that the identification
code information set includes the transmitter information; or checking, by the receive
terminal, whether the transmitter information includes a right to open a controlled
door controlled by the receive terminal, and if yes, outputting a control signal for
controlling unlocking of a controllable lock.
Step 503: Output the control signal for controlling unlocking of the controllable
lock to control unlocking of the controllable lock.
Step 504: Do not output the control signal for controlling unlocking of the controllable
lock, so that the controllable lock maintains a locked state.
Embodiment 3
[0028] Generally, when software is installed in a mobile phone, a password used as an access
identification code is loaded into an SD card of the mobile phone in a text form for
use. To change the password, it is only necessary to generate a new password on a
computer and save the new password to a text file, and then replace old text information
in the SD card of the mobile phone. With the increase of users in a photonic access
control system, this manner already cannot meet market requirements, and there is
a risk of leakage when a password is stored in an SD card of a mobile phone.
[0029] The access control system in this embodiment further includes an identification code
allocation server. When a transmitter is a mobile terminal, the mobile terminal performs
data communication with the identification code allocation server by using one or
more information networks. The network may be at least one of the Internet, a local
area network, a Wi-Fi network, and a mobile communication network (GSM, CDMA, WCDMA,
TD-LTE, LTE, or the like). A method for acquiring an identification code by the mobile
terminal is: sending an identification code acquisition request to the identification
code allocation server through the Internet or local area network, where the identification
code acquisition request includes information associated with the mobile terminal,
so that the identification code allocation server sends a unique identification code
to the mobile terminal associated with the request according to the identification
code acquisition request. The identification code acquisition request may be transmitted
by a requester by using the mobile terminal, or may be transmitted by an administrator
by using an access control system platform.
[0030] In an embodiment, when software is installed in a mobile terminal, a valid password
or a null password may be included therewith. After the software is installed in the
mobile terminal, the mobile terminal sends an identification code acquisition request
to the identification code allocation server. And the identification code allocation
server sends a unique identification code corresponding to the mobile terminal to
the mobile terminal by using SMS according to the request. The foregoing right information
is received manually on the mobile terminal. A user sets an unlocking right ID (encrypted)
on the mobile terminal according to the received identification code, and writes the
unlocking right ID into the mobile terminal. Thereby, users are allowed to set correct
passwords by themselves.
[0031] Considering uniqueness, confidentiality, and controllability features of identification
codes, the identification code allocation server allocates only one identification
code for each identification code acquisition request.
[0032] In the following description, a mobile terminal is a mobile phone, which is as an
example to describe a process in which the mobile terminal acquires an identification
code from an identification code allocation server through a local area network or
the Internet.
[0033] S101. Configure a database, create a database instance, and create a database table
for storing an identification code (hereinafter referred to as an ID for short).
[0034] S102. Implement an ID allocation function by using a popular three-layer architecture
webservice+Spring+Hibernate of a Java platform website, implement an ID management
function of the website by using a three-layer architecture Struts+Spring+Hibernate,
and perform source encryption and channel encryption on communication data, where
an AES encryption algorithm is used for source encryption, and an SSL encryption algorithm
is used for channel encryption.
[0035] S103. A login portal must be set before a mobile phone communicates with a server
in a local area network or the Internet. For example, a Wi-Fi router is connected
to the local area network, and then the mobile phone is connected to the Wi-Fi router.
Alternatively, an Internet router is connected to the Internet, and then the mobile
phone is connected to the Internet router.
[0036] S104. To ensure security of an administrator, the administrator must log in to a
website of an identification code allocation server by using a password, and can change
the password. This password is static, that is, the password for login each time is
consistent.
[0037] S105. Determine whether the password is consistent. If the password is consistent,
it indicates that the one currently logging in is an administrator. If the password
is inconsistent, an input error may occur, or the one currently logging in is not
an administrator. To avoid a third-party attack, the number of allowed password retries
is set to 5, so that an account is locked if the number of password retries exceeds
5. Each administrator maintains a login password. A length, complexity, and periodicity
of the password may be set. For example, the length of the password can be set to
10 characters, including numbers, letters, and special symbols, and the password should
be changed every month. If the administrator forgets the password, the administrator
may tell a cloud administrator to reset the password.
[0038] S106. A user clicks an "Acquire ID" button on a mobile phone photonic client, and
then the administrator can prompt, on the website of the server, that a mobile phone
is acquiring an ID.
[0039] S107. To allow only one mobile phone to acquire an ID each time, the quantity of
allocated IDs is set to one. When a mobile phone is acquiring an ID, it is possible
that another illegal user that has downloaded mobile phone software is also acquiring
an ID. For example, user A is a dweller in a community, user B is not a dweller in
the community, and user B clicks "Acquire ID" earlier than user A. In this case, how
can user A and user B be distinguished? The users may be distinguished through interaction
between the administrator and the users. For example, the administrator sets the quantity
of allocated IDs to 1; when user B clicks "Acquire ID" earlier than user A, the mobile
phone of user B prompts "Acquiring an ID", and the mobile phone of user A prompts
"Acquiring an ID fails". In this case, it is displayed on an administrator operation
interface that a user is acquiring an ID. User A tells the administrator that acquiring
an ID fails. Obviously, the ID being acquired is not an ID of user A, but an ID of
illegal user B. In this case, the administrator interrupts the acquisition of an ID
without hesitation, and clicks to refuse acquiring an ID, and the mobile phone of
user B prompts "Acquiring an ID is refused". Then the mobile phone of user B can retry
only after waiting for a period of time, but user A can retry immediately. The retry
process is the same as that described above. If ID allocation is authorized successfully,
S108 is performed. If ID allocation fails to be authorized, S109 is performed.
[0040] S108. The mobile phone photonic client performs channel decryption and source decryption
on the acquired data. The decryption method is symmetric to the foregoing encryption
method. After a plain text is obtained through decryption, "Acquiring an ID succeeds"
is prompted.
[0041] S109. The mobile phone photonic client prompts "Acquiring an ID fails".
[0042] S110. The mobile phone photonic client may be set to retry acquiring an ID after
a period of time.
[0043] Sill. Save the ID that is generated by decrypted, and when the ID is saved, AES encryption
needs to be performed on the ID by using a unique identity of the mobile phone as
a key.
[0044] In other embodiments, the password for administrator to log in to the identification
code allocation server may also be generated dynamically. The login may be implemented
by the administrator by inputting the password and a verification code, that is, the
password keeps unchanged, and the verification code changes each time.
[0045] In this embodiment, an Advanced Encryption Standard (AES) encryption is used, and
a unique identity of the mobile phone is used as a key to perform encryption to avoid
information fraud. A Java SSH three-layer architecture model is used to support an
application platform of the website to ensure quality and reuse of programs. An interactive
ID allocation process ensures uniqueness of an allocated ID.
[0046] In the invention, the identification code allocation server includes a QR code generation
module. The identification code allocation server generates, according to an identification
code acquisition request input by a user, a bound verification code and identification
code, generates a QR code of the verification code according to the verification code
by using the QR code generation module, and displays the QR code of the verification
code; the mobile terminal includes a QR code scanning module, and the mobile terminal
scans the QR code of the verification code by using the QR code scanning module to
extract the verification code, and sends a request for acquiring the identification
code corresponding to the verification code to the identification code allocation
server, where the identification code acquisition request sent by the mobile terminal
includes the verification code that is extracted by the mobile terminal from the QR
code and identity information of the mobile terminal. After receiving the identification
code acquisition request sent by the mobile terminal, the identification code allocation
server sends the identification code corresponding to the verification code to the
mobile terminal. A specific process is as follows:
S201. After uploading mobile phone photonic client software to an application store,
generate a QR code of a download website by using a QR code generation tool. A mobile
phone scans the generated QR code by using a QR code scanning tool, and obtains the
download website. The mobile phone photonic client software may be downloaded by clicking
"Download". Then the software is installed. When the software is installed for the
first time, there is no ID information. Therefore, "Acquire an ID by setting" is prompted.
S202. Configure a database, create a database instance, and create a database table
for storing an ID.
S203. Implement an ID allocation function by using a popular three-layer architecture
webservice+Spring+Hibernate of a Java platform website, implement an ID management
function of the website by using a three-layer architecture Struts+Spring+Hibernate,
and perform source encryption and channel encryption on communication data, where
an AES encryption algorithm is used for source encryption, and an SSL encryption algorithm
is used for channel encryption.
S204. To ensure security of an administrator, the administrator must log in by using
a password, and can change the password. The password is generated dynamically, which
is implemented by the administrator by inputting the password and a verification code,
that is, the password keeps unchanged, and the verification code changes each time.
S205. Determine whether the password is consistent. If the password is consistent,
it indicates that the one currently logging in is an administrator. If the password
is inconsistent, an input error may occur, or the one currently logging in is not
an administrator. To avoid a third-party attack, the number of allowed password retries
is set to 5, so that an account is locked if the number of password retries exceeds
5. Each administrator maintains a login password. A length, complexity, and periodicity
of the password may be set. For example, the length of the password is set to 10 characters,
including numbers, letters, and special symbols, and the password should be changed
every month. If the administrator forgets the password, the administrator may tell
a cloud administrator to reset the password.
S206. The administrator sends a request to a web server by using a web browser or
another client. The web server randomly generates one or more verification codes at
the back end and randomly generates one or more IDs, and binds the generated verification
code with the ID, and then generates a QR code by using a QR code generation tool.
S207. A mobile phone photonic client scans the QR code of the verification code by
using a QR code decoding tool, and extracts the verification code. After "Acquire
ID" is clicked on the mobile phone photonic client, the administrator can prompt,
on the website of the server, that a mobile phone is acquiring an ID.
S208. To allow only one mobile phone to acquire an ID each time, the quantity of allocated
IDs is set to one. When a mobile phone is acquiring an ID, it is possible that another
illegal user that has downloaded mobile phone software is also acquiring an ID. For
example, user A is a dweller in a community, user B is not a dweller in the community,
and user B clicks "Acquire ID" earlier than user A. In this case, how can user A and
user B be distinguished? The users may be distinguished through interaction between
the administrator and the users. For example, the administrator sets the quantity
of allocated IDs to 1; when user B clicks "Acquire ID" earlier than user A, the mobile
phone of user B prompts "Acquiring an ID", and the mobile phone of user A prompts
"Acquiring an ID fails". In this case, it is displayed on an administrator operation
interface that a user is acquiring an ID. User A tells the administrator that acquiring
an ID fails. Obviously, the ID being acquired is not an ID of user A, but an ID of
illegal user B. In this case, the administrator interrupts the acquisition of an ID
without hesitation, and clicks to refuse acquiring an ID, and the mobile phone of
user B prompts "Acquiring an ID is refused". Then the mobile phone of user B can retry
only after waiting for a period of time, but user A can retry immediately. The retry
process is the same as that described above. If ID allocation is authorized successfully,
S209 is performed. If ID allocation fails to be authorized, S210 is performed.
S209. The mobile phone photonic client performs channel decryption and source decryption
on the acquired data. The decryption method is symmetric to the foregoing encryption
method. After a plain text is obtained through decryption, "Acquiring an ID succeeds"
is prompted.
S210. The mobile phone photonic client prompts "Acquiring an ID fails".
S211. The mobile phone photonic client may be set to retry acquiring an ID after a
period of time.
S212. Save the ID that is generated and decrypted, and when the ID is saved, AES encryption
needs to be performed on the ID by using a unique identity of the mobile phone as
a key.
[0047] In this embodiment, the QR code generation and decoding tools need to be used to
download the mobile phone photonic client software, and the QR code generation and
decoding tools also need to be used when a verification code is used to perform communication
with the website. The administrator password is generated dynamically to maximally
ensure security of the ID allocated to the administrator. A high-security AES encryption
and decryption algorithm is used, and a unique identity of the mobile phone is used
as a key to perform encryption to avoid information fraud. A Java SSH three-layer
architecture model is used to support an application platform of the website to ensure
quality and reuse of programs. An interactive ID allocation process ensures uniqueness
of an allocated ID.
[0048] In another specific instance, the identification code allocation server generates,
according to a mobile terminal number (for example, a mobile phone number) input by
the user, a unique identification code corresponding to the mobile terminal number,
and the mobile terminal obtains the identification code from the identification code
allocation server by sending an identification code acquisition request that carries
the mobile terminal number. A specific process of this embodiment is as follows:
S301. Configure a database, create a database instance, and create a database table
for storing an ID.
S302. Use a popular three-layer model of a .net platform website: 1. View layer: use
a configuration file for implementation; 2. Model layer: compile all entity classes
and service logic; 3. Control layer: implement redirection of different results according
to the service logic of the model layer. Implement an ID allocation function, implement
an ID management function of the website by using the foregoing model, and perform
source encryption and channel encryption on communication data, where an AES encryption
algorithm is used for source encryption, and an SSL encryption algorithm is used for
channel encryption.
S303. A login portal must be set before a mobile phone communicates with an Internet
server. For example, an Internet router is connected to the Internet, and then the
mobile phone is connected to the Internet router.
S304. To ensure security of the administrator, before operating ID allocation software,
the administrator must log in by inputting a password, and can change the password.
This password is static, that is, the password for login each time is consistent.
S305. Determine whether the password is consistent. If the password is consistent,
it indicates that the one currently logging in is an administrator. If the password
is inconsistent, an input error may occur, or the one currently logging in is not
an administrator. To avoid a third-party attack, the number of allowed password retries
is set to 5, so that an account is locked if the number of password retries exceeds
5. Each administrator maintains a login password. A length, complexity, and periodicity
of the password may be set. For example, the length of the password is set to 10 characters,
including numbers, letters, and special symbols, and the password should be changed
every month. If the administrator forgets the password, the administrator may tell
a cloud administrator to reset the password.
S306. The administrator inputs a unique identity IMSI of the mobile phone by using
the ID allocation software, and then clicks "Generate", and then an unused random
ID may be generated and bound with the mobile phone number.
S307. A mobile phone photonic client acquires the unique identity IMSI of the mobile
phone by using a program. After an "Acquire ID" button is clicked on the mobile phone
photonic client, the mobile phone photonic client sends an HTTP request carrying the
mobile phone number to a web server.
S308. After receiving the HTTP request, the web server performs the following processing:
first determining whether the received IMSI is recorded in a binding list generated
in S106; and if the IMSI is recorded, extracting the ID corresponding to the IMSI,
and returning the ID to a photonic key of the mobile phone, and going to S309; or
if the IMSI is not recorded, returning authorization failure information, and going
to S310.
S309. The mobile phone photonic client acquires data through the network, and prompts
"Acquiring an ID succeeds".
S310. The mobile phone photonic client acquires data through the network, and prompts
"Acquiring an ID fails".
S311. The mobile phone photonic client may be set to retry acquiring an ID after a
period of time.
S312. Save the ID that is generated and decrypted, and when the ID is saved, AES encryption
needs to be performed on the ID by using a unique identity of the mobile phone as
a key.
[0049] In this embodiment, the administrator password is generated dynamically to maximally
ensure security of the ID allocated to the administrator, a high-security AES encryption
and decryption algorithm is used, and a unique identity of the mobile phone is used
as a key to perform encryption to avoid information fraud. To control the allocation
process, the administrator registers an IMSI of a user beforehand, and binds the IMSI
with an ID. Later, when the user uses the mobile phone photonic key to request an
ID, an ID is allocated for each IMSI. The web server uses a three-layer architecture
of a .net platform to support an application platform of the website to ensure quality
and reuse of programs. An interactive ID allocation process ensures uniqueness of
an allocated ID.
Embodiment 4
[0050] A difference from Embodiment 3 lies in that an identification code allocation device
is a host computer, where the host computer generates and deletes an identification
code by using software. In this embodiment, a transmitter may be a mobile phone photonic
client, a light pen photonic client, or the like, and the transmitter is connected
to the host computer by using a data line to acquire an identification code. Using
a mobile phone photonic client as an example, a specific process of this embodiment
is as follows:
S101. Configure a database, create a database instance, and create a database table
for storing an ID.
S102. Compile ID allocation software for a host computer by using Visual C# 2008,
randomly select a unique ID and an administrator password from a mysql database, perform
AES encryption on the ID and administrator password, and save the ID and administrator
password to a file in a memory card of a mobile phone.
S103. Install mobile phone photonic client software on a mobile phone from an application
store or an optical disc. Then an administrator inputs the administrator password
that is generated by the ID allocation software of the host computer beforehand.
S104. A mobile phone photonic client decrypts the encrypted file that is generated
just now in the memory card, and compares the input administrator password with the
decrypted administrator password. If the password is correct, S105 is performed. If
the password is incorrect, S106 is performed.
S105. Click an "Acquire ID" button on the mobile phone photonic client, and perform
AES decryption on the encrypted file that is generated just now in the memory card.
S106. Select whether to retry inputting the administrator password, and if yes, go
to S103, or otherwise, end the process.
S107. Save the ID that is generated by decryption, and when the ID is saved, AES encryption
needs to be performed on the ID by using a unique identity of the mobile phone as
a key.
[0051] In this embodiment, a high-security AES encryption and decryption algorithm is used,
and a unique identity of the mobile phone is used as a key to perform encryption to
avoid information fraud.
[0052] In the foregoing embodiments, the identification code allocation device and the access
control management server may be two independent devices that may perform data communication
with each other, or may be integrated into one device.
[0053] When the authentication system is applied to other systems that require authorization,
the principle and working process of the authentication system are similar. For example,
the authentication system is a ticket system or a metro system. The ticket system
or the metro system further includes a gate, where the controller is further communicatively
connected to the gate, and after performing a second right authentication on transmitter
information, the controller determines whether to output a gate control signal to
the gate to control the gate to open according to an authentication result; or the
authentication system is a transaction system, the transaction system further includes
a cash register or a POS machine, where the controller is further communicatively
connected to the cash register or the POS machine, and after performing a second right
authentication on transmitter information, the controller determines, according to
an authentication result, whether to output a cash control signal to the cash register
or the POS machine to control the cash register or the POS machine to pay or receive
cash. The specific process is not further described herein.
[0054] Although detailed descriptions of the present invention are further provided with
reference to specific embodiments above, it cannot be considered that specific implementation
of the present invention is limited to those descriptions. A person of ordinary skill
in the technical field of the present invention may further make several simple derivations
or replacements without departing from the conception of the invention.
INDUSTRIAL APPLICABILITY
[0055] In the embodiments of the present invention, a security risk caused by uncontrolled
transmission of a light signal of an identification code of a transmitter by the transmitter
is reduced. After the transmitter transmits the light signal of the identification
code of the transmitter, a receiver performs a second right authentication on the
received light signal. In this way, security of an authentication system is further
improved.
1. An authentication system, comprising a transmit terminal, a receive terminal, and
a management server (50), the transmit terminal comprises a transmitter (10), the
receive terminal comprises a receiver (20) and a controller (30), and the controller
(30) is communicatively connected to the receiver (20) and the management server (50)
respectively, wherein:
the management server (50) stores an identification code information set corresponding
to each receiver (20);
the receiver (20) comprises an information transmit module (21) and a light receive
module (22), where the information transmit module (21) and the light receive module
(22) are communicatively connected to the controller (30) respectively, the information
transmit module (21) externally propagates the acquired identification code information
set, and the light receive module (22) performs at least photoelectric conversion
after receiving a light signal from the transmitter (10), and outputs transmitter
information to the controller (30);
the controller (30) performs a second right authentication on the transmitter information
after receiving the transmitter information; and
the transmitter (10) comprises a processor (11), an information receive module (12),
and a light transmit module (13), where the processor (11) is connected to the information
receive module (12) and the light transmit module (13) respectively, the information
receive module (12) transmits the identification code information set to the processor
(11) after receiving the identification code information set transmitted by the information
transmit module (21), and the processor (11) performs, according to the received identification
code information set, a first right authentication on whether the transmitter (10)
has operation rights, and controls an enable state of the light transmit module (13)
according to an authentication result;
wherein the transmitter (10) is a mobile terminal, and the authentication system further
comprises an identification code allocation server, the mobile terminal performs data
communication with the identification code allocation server by using one or more
information networks, and the identification code allocation server sends a unique
identification code to the mobile terminal associated with the request, according
to an identification code acquisition request, and the identification code acquisition
request comprises information associated with the mobile terminal;
wherein the identification code allocation server comprises a QR code generation module,
and the identification code allocation server generates a bound verification code
and identification code according to the identification code acquisition request input
by a user, and generates a QR code of the verification code according to the verification
code by using the QR code generation module; the mobile terminal comprises a QR code
scanning module, and the mobile terminal scans the QR code of the verification code
by using the QR code scanning module to extract the verification code, and sends a
request for acquiring the identification code corresponding to the verification code
to the identification code allocation server, and the identification code acquisition
request sent by the mobile terminal comprises the verification code that is extracted
by the mobile terminal from the QR code and identity information of the mobile terminal,
and the identification code allocation server sends the identification code corresponding
to the verification code to the mobile terminal.
2. The authentication system according to claim 1, wherein the identification code information
set comprises unique identification code information of all transmitters corresponding
to the receiver (20), and the processor (11) performs the first right authentication
on whether the transmitter (10) has operation rights comprises: the processor (11)
compares a unique identification code of the transmitter (10) with the received identification
code information set, and if the received identification code information set comprises
an identification code that is the same as the unique identification code of the transmitter
(10), controls the light transmit module (13) to switch to a working state that allows
converting transmitter information of the transmitter (10) into a light signal for
transmission, and the transmitter information comprises at least the unique identification
code of the transmitter (10).
3. The authentication system according to claim 1, wherein the identification code information
set comprises identity information of the receive terminal, the transmitter (10) stores
identity information of all receive terminals that the transmitter (10) has rights
to operate, and the processor (11) performs the first right authentication on whether
the transmitter (10) has operation rights comprises: the processor (11) compares the
received identification code information set with the identity information of all
the receive terminals that the transmitter (10) has the rights to operate which is
stored by the transmitter (10), and if the identity information of all the receive
terminals that the transmitter (10) has the rights to operate which is stored by the
transmitter (10) comprises the identification code information set, controls the light
transmit module (13) to switch to a working state that allows converting transmitter
information of the transmitter (10) into a light signal for transmission, and the
transmitter information comprises at least a unique identification code of the transmitter
(10).
4. The authentication system according to claim 1, wherein the information transmit module
(21) directly obtains the identification code information set from the management
server (50), and/or the controller (30) obtains an identification code information
set corresponding to the receiver (20) from the management server (50), and transmits
the identification code information set to the information transmit module (21) of
the receiver (20).
5. The authentication system according to claim 1, wherein the transmitter (10) further
comprises a first encryption module configured to encrypt transmitter information
of the transmitter (10), the first encryption module is connected between the processor
(11) and the light transmit module (13); and the receiver (20) further comprises a
second decryption module, and the second decryption module is connected between the
light receive module (22) and the controller (30), and configured to perform signal
decryption after receiving a signal obtained through photoelectric conversion and
output by the light receive module (22).
6. The authentication system according to claim 1, wherein the receiver (20) further
comprises a second encryption module, the second encryption module is connected between
the controller (30) and the information transmit module (21), and configured to encrypt
the identification code information set received from the controller (30) and output
the encrypted identification code information set to the information transmit module
(21); the transmitter (10) further comprises a first decryption module, the first
decryption module is connected between the processor (11) and the information receive
module (12), and configured to decrypt the identification code information set received
by the information receive module (12), and output the decrypted identification code
information set to the processor (11).
7. The authentication system according to claim 1, wherein the identification code allocation
server generates a unique identification code corresponding to the mobile terminal
number according to a mobile terminal number input by the user, and the mobile terminal
obtains the identification code from the identification code allocation server by
sending an identification code acquisition request that carries the mobile terminal
number.
8. The authentication system according to claim 1, wherein the identification code allocation
server allocates an identification code for each identification code acquisition request.
9. The authentication system according to claim 1, wherein the authentication system
further comprises a host computer configured to generate and delete an identification
code, and the transmitter (10) is connected to the host computer by using a data line,
to acquire the identification code.
10. A transmit terminal, wherein the transmit terminal comprises a transmitter (10), and
the transmitter (10) comprises a processor (11), an information receive module (12),
and a light transmit module (13), where the processor (11) is connected to the information
receive module (12) and the light transmit module (13) respectively, the information
receive module (12) transmits the identification code information set to the processor
(11) after receiving an identification code information set, and the processor (11)
performs a first right authentication on whether the transmitter (10) has operation
rights according to the received identification code information set, and controls
an enable state of the light transmit module (13) according to an authentication result;
wherein the transmitter (10) is a mobile terminal, and the authentication system further
comprises an identification code allocation server, the mobile terminal performs data
communication with the identification code allocation server by using one or more
information networks, and the identification code allocation server sends a unique
identification code to the mobile terminal associated with the request, according
to an identification code acquisition request, and the identification code acquisition
request comprises information associated with the mobile terminal;
wherein the identification code allocation server comprises a QR code generation module,
and the identification code allocation server generates a bound verification code
and identification code according to the identification code acquisition request input
by a user, and generates a QR code of the verification code according to the verification
code by using the QR code generation module; the mobile terminal comprises a QR code
scanning module, and the mobile terminal scans the QR code of the verification code
by using the QR code scanning module to extract the verification code, and sends a
request for acquiring the identification code corresponding to the verification code
to the identification code allocation server, and the identification code acquisition
request sent by the mobile terminal comprises the verification code that is extracted
by the mobile terminal from the QR code and identity information of the mobile terminal,
and the identification code allocation server sends the identification code corresponding
to the verification code to the mobile terminal.
11. A method for right authentication in an authentication system, wherein the authentication
system comprises a transmit terminal and a receive terminal, and the transmit terminal
comprises a transmitter (10), the receive terminal comprises a receiver (20) and a
controller (30) that are connected, and the method comprises:
externally propagating, by the receiver (20), an acquired identification code information
set corresponding to the receiver (20);
after receiving the identification code information set transmitted by the receiver
(20), performing a first right authentication on whether the transmitter (10) has
operation rights by the transmitter (10) according to the received identification
code information set, and determining whether to allow converting transmitter information
of the transmitter (10) into a light signal for transmission according to an authentication
result, where the transmitter (10) information comprises at least a unique identification
code of the transmitter (10); and
after the receive terminal receives, by using the light receive module (22), the transmitter
information that is transmitted by the transmitter (10) in a light signal form, performing
a second right authentication on the transmitter information by the controller (30);
wherein the transmitter (10) is a mobile terminal, and the authentication system further
comprises an identification code allocation server, the mobile terminal performs data
communication with the identification code allocation server by using one or more
information networks, and the identification code allocation server sends a unique
identification code to the mobile terminal associated with the request, according
to an identification code acquisition request, and the identification code acquisition
request comprises information associated with the mobile terminal;
wherein the identification code allocation server comprises a QR code generation module,
and the identification code allocation server generates a bound verification code
and identification code according to the identification code acquisition request input
by a user, and generates a QR code of the verification code according to the verification
code by using the QR code generation module; the mobile terminal comprises a QR code
scanning module, and the mobile terminal scans the QR code of the verification code
by using the QR code scanning module to extract the verification code, and sends a
request for acquiring the identification code corresponding to the verification code
to the identification code allocation server, and the identification code acquisition
request sent by the mobile terminal comprises the verification code that is extracted
by the mobile terminal from the QR code and identity information of the mobile terminal,
and the identification code allocation server sends the identification code corresponding
to the verification code to the mobile terminal.
12. A right authentication method for a transmit terminal, comprising:
receiving an identification code information set transmitted by a receiver (20);
performing a first right authentication on whether the transmit terminal has operation
rights according to the received identification code information set; and
determining whether to allow converting transmitter information of the transmit terminal
into a light signal for transmission according to an authentication result, where
the transmitter information comprises at least a unique identification code corresponding
to the transmit terminal;
wherein the transmit terminal comprises a transmitter (10), the transmitter (10) is
a mobile terminal, and the authentication system further comprises an identification
code allocation server, the mobile terminal performs data communication with the identification
code allocation server by using one or more information networks, and the identification
code allocation server sends a unique identification code to the mobile terminal associated
with the request, according to an identification code acquisition request, and the
identification code acquisition request comprises information associated with the
mobile terminal;
wherein the identification code allocation server comprises a QR code generation module,
and the identification code allocation server generates a bound verification code
and identification code according to the identification code acquisition request input
by a user, and generates a QR code of the verification code according to the verification
code by using the QR code generation module; the mobile terminal comprises a QR code
scanning module, and the mobile terminal scans the QR code of the verification code
by using the QR code scanning module to extract the verification code, and sends a
request for acquiring the identification code corresponding to the verification code
to the identification code allocation server, and the identification code acquisition
request sent by the mobile terminal comprises the verification code that is extracted
by the mobile terminal from the QR code and identity information of the mobile terminal,
and the identification code allocation server sends the identification code corresponding
to the verification code to the mobile terminal.
13. The method according to claim 12, wherein the identification code information set
comprises unique identification code information of all transmitters corresponding
to the receiver (20), and performing the first right authentication on whether the
transmit terminal has operation rights according to the received identification code
information set comprises:
comparing a unique identification code of the transmitter (10) with the received identification
code information set by a transmitter (10);
if the received identification code information set comprises an identification code
that is the same as the unique identification code of the transmitter (10), allowing
converting the transmitter (10) information of the transmit terminal into a light
signal for transmission by using a light transmit module (13); or
the identification code information set comprises identity information of a receive
terminal, the transmit terminal stores identity information of all receive terminals
that the transmit terminal has rights to operate, and performing the first right authentication
on whether the transmit terminal has operation rights according to the received identification
code information set comprises:
comparing the received identification code information set with the identity information
of all the receive terminals that the transmit terminal has the rights to operate
which is stored by the transmit terminal, and if the identity information of all the
receive terminals that the transmit terminal has the rights to operate which is stored
by the transmit terminal comprises the identification code information set, allowing
converting the transmitter information of the transmit terminal into a light signal
for transmission by using a light transmit module (13).
1. Authentifizierungssystem, umfassend ein Sendeterminal, ein Empfangsterminal und einen
Management-Server (50), wobei das Sendeterminal einen Sender (10) umfasst, das Empfangsterminal
einen Empfänger (20) und eine Steuerung (30) umfasst und die Steuerung (30) mit dem
Empfänger (20) und dem Management-Server (50) jeweils in Kommunikationsverbindung
steht, wobei:
der Management-Server (50) einen Identifizierungscodeinformationssatz speichert, der
jedem Empfänger (20) entspricht;
der Empfänger (20) ein Informationssendemodul (21) und ein Lichtempfangsmodul (22)
umfasst, wobei das Informationssendemodul (21) und das Lichtempfangsmodul (22) mit
der Steuerung (30) jeweils in Kommunikationsverbindung stehen, das Informationssendemodul
(21) den erfassten Identifikationscodeinformationssatz extern überträgt, und das Lichtempfangsmodul
(22) mindestens fotoelektrische Umwandlung nach Empfang eines Lichtsignals vom Sender
(10) durchführt und Senderinformation an die Steuerung (30) ausgibt;
die Steuerung (30) eine zweite Rechteauthentifizierung an der Senderinformation nach
Empfang der Senderinformation durchführt; und
der Sender (10) einen Prozessor (11), ein Informationsempfangsmodul (12) und ein Lichtsendemodul
(13) aufweist, wobei der Prozessor (11) mit dem Informationsempfangsmodul (12) und
dem Lichtsendemodul (13) jeweils verbunden ist, das Informationsempfangsmodul (12)
den Identifikationscodeinformationssatz zum Prozessor (11) nach Empfang des von dem
Informationssendemodul (21) gesendeten Identifikationscodeinformationssatzes sendet,
und der Prozessor (11), gemäß dem empfangenen Identifikationscodeinformationssatz,
eine erste Rechteauthentifizierung daran vornimmt, ob der Sender Betriebsrechte hat,
und einen Freigabezustand des Lichtsendemoduls (13) gemäß einem Authentifizierungsergebnis
steuert;
wobei der Sender (10) ein mobiles Terminal ist und das Authentifizierungssystem ferner
einen Identifikationscodezuteilungsserver aufweist, das mobile Terminal Datenkommunikation
mit dem Identifikationscodezuteilungsserver durch Verwendung von einem oder mehreren
Informationsnetzwerken durchführt und der Identifikationscodezuteilungsserver einen
eindeutigen Identifikationscode, gemäß einer Identifikationscodeerfassungsanfrage,
zu dem mit der Anfrage verbundenen mobilen Terminal sendet und die Identifikationscodeerfassungsanfrage
mit dem mobilen Terminal verbundene Information umfasst;
wobei der Identifikationscodezuteilungsserver ein QR-Code-Erzeugungsmodul aufweist
und der Identifikationscodezuteilungsserver einen begrenzten Verifizierungscode und
Identifikationscode entsprechend der von einem Benutzer eingegebenen Identifikationscodeerfassungsanfrage
erzeugt, und einen QR-Code des Verifizierungscodes gemäß dem Verifizierungscode durch
Verwendung des QR-Code-Erzeugungsmoduls erzeugt; das mobile Terminal ein QR-Code-Scanningmodul
aufweist, und das mobile Terminal den QR-Code des Verifizierungscodes durch Verwendung
des QR-Code-Scanningmoduls scannt, um den Verifizierungscode zu extrahieren, und eine
Anfrage zur Erfassung des Identifikationscodes entsprechend dem Verifizierungscode
an den Identifikationscodezuteilungsserver sendet, und die von dem mobilen Terminal
gesendete Identifikationscodeerfassungsanfrage den Verifizierungscode aufweist, der
von dem mobilen Terminal aus dem QR-Code und Identitätsinformation des mobilen Terminals
extrahiert ist, und der Identifikationscodezuteilungsserver den Identifikationscode,
der dem Verifizierungscode entspricht, an das mobile Terminal sendet.
2. Authentifizierungssystem nach Anspruch 1, wobei der Identifizierungscodeinformationssatz
eindeutige Identifizierungscodeinformation aller Sender entsprechend dem Empfänger
(20) umfasst und der Prozessor (11) die erste Rechteauthentifizierung daran vornimmt,
ob der Sender (10) Betriebsrechte hat, umfassend: der Prozessor (11) vergleicht einen
eindeutigen Identifizierungscode des Senders (10) mit dem empfangenen Identifizierungscodeinformationssatz,
und wenn der empfangene Identifizierungscodeinformationssatz einen Identifizierungscode
umfasst, der derselbe wie der eindeutige Identifizierungscode des Senders (10) ist,
das Lichtsendemodul (13) ansteuert, um in einen Arbeitszustand zu wechseln, der ein
Konvertieren von Senderinformation des Senders (10) in ein Lichtsignal zum Senden
zulässt, und die Senderinformation mindestens den eindeutigen Identifizierungscode
des Senders (10) umfasst.
3. Authentifizierungssystem nach Anspruch 1, wobei der Identifizierungscodeinformationssatz
Identitätsinformation des Empfangsterminals umfasst, der Sender (10) Identitätsinformation
aller Empfangsterminals, dass der Sender (10) Rechte für den Betrieb hat, speichert,
und der Prozessor (11) die erste Rechteauthentifizierung daran vornimmt, ob der Sender
(10) Betriebsrechte hat, umfassend: der Prozessor (11) vergleicht den empfangenen
Identifizierungscodeinformationssatz mit der Identitätsinformation aller Empfangsterminals,
dass der Sender die Betriebsrechte hat, was von dem Sender (10) gespeichert ist, und
wenn die Identitätsinformation aller Empfangsterminals, dass der Sender (10) die Rechte
zum Betrieb hat, was von dem Sender gespeichert ist, den Identifizierungscodeinformationssatz
umfasst, das Lichtsendemodul (13) steuert, um in einen Arbeitszustand zu wechseln,
der eine Umwandlung von Senderinformation des Senders (10) in ein Lichtsignal zum
Senden zulässt, und die Senderinformation mindestens einen eindeutigen Identifizierungscode
des Senders (10) umfasst.
4. Authentifizierungssystem nach Anspruch 1, wobei das Informationssendemodul (21) den
Identifizierungscodeinformationssatz vom Management-Server (50) direkt erhält und/oder
die Steuerung (30) einen dem Empfänger (20) entsprechenden Identifizierungscodeinformationssatz
vom Management-Server (50) enthält, und den Identifizierungscodeinformationssatz zum
Informationssendemodul (21) des Empfängers (20) sendet.
5. Authentifizierungssystem nach Anspruch 1, wobei der Sender (10) ferner ein erstes
Verschlüsselungsmodul aufweist, das konfiguriert ist, um Senderinformation des Senders
(10) zu verschlüsseln, das erste Verschlüssungsmodul zwischen dem Prozessor (11) und
dem Lichtsendemodul (13) angeschlossen ist; und der Empfänger (20) ferner ein zweites
Entschlüsselungsmodul aufweist, und das zweite Entschlüsselungsmodul zwischen dem
Lichtempfangsmodul (22) und der Steuerung (30) angeschlossen ist, und konfiguriert
ist, um eine Signalentschlüsselung nach Empfang eines Signals durchzuführen, das durch
fotoelektrische Umwandlung erhalten und von dem Lichtempfangsmodul (22) ausgegeben
ist.
6. Authentifizierungssystem nach Anspruch 1, wobei der Empfänger (20) ferner ein zweites
Verschlüsselungsmodul aufweist, das zweite Verschlüsselungsmodul zwischen der Steuerung
(30) und dem Informationssendemodul (21) angeschlossen und konfiguriert ist, um den
von der Steuerung (30) empfangenen Identifizierungscodeinformationssatz zu verschlüsseln
und den verschlüsselten Informationscodeinformationssatz an das Informationssendemodul
(21) auszugeben; der Sender (10) ferner ein erstes Entschlüsselungsmodul aufweist,
das erste Entschlüsselungsmodul zwischen dem Prozessor (11) und dem Informationsempfangsmodul
(12) angeschlossen ist und konfiguriert ist, um den von dem Informationsempfangsmodul
(12) empfangenen Identifizierungscodeinformationssatz zu entschlüsseln und den entschlüsselten
Identifizierungscodeinformationssatz an den Prozessor (11) auszugeben.
7. Authentifizierungssystem nach Anspruch 1, wobei der Identifizierungscodezuteilungsserver
einen eindeutigen Identifizierungscode, der der mobilen Terminalnummer entspricht,
gemäß einer von dem Benutzer eingegebenen Terminalnummer erzeugt, und das mobile Terminal
den Identifizierungscode vom Identifizierungscodezuteilungsserver durch Senden einer
Identifizierungscodeerfassungsanfrage, die die mobile Terminalnummer trägt, erhält.
8. Authentifizierungssystem nach Anspruch 1, wobei der Identifizierungscodezuteilungsserver
einen Identifizierungscode für jede Identifizierungscodeerfassungsanfrage zuteilt.
9. Authentifizierungssystem nach Anspruch 1, wobei das Authentifizierungssystem ferner
einen Host-Computer aufweist, der konfiguriert ist, um einen Identifizierungscode
zu erzeugen und zu löschen, und der Sender (10) mit dem Host-Computer durch Verwendung
einer Datenleitung verbunden ist, um den Identifizierungscode zu erfassen.
10. Sendeterminal, wobei das Sendeterminal einen Sender (10) aufweist und der Sender (10)
einen Prozessor (11), ein Informationsempfangsmodul (12) und ein Lichtsendemodul (13)
aufweist, wobei der Prozessor (11) mit dem Informationsempfangsmodul (12) und dem
Lichtsendemodul (13) jeweils verbunden ist, das Informationsempfangsmodul (12) den
Identifizierungscodeinformationssatz zum Prozessor (11) nach Empfangen eines Identifizierungscodeinformationssatzes
sendet, und der Prozessor (11) eine erste Rechteauthentifizierung gemäß dem empfangenen
Identifizierungscodeinformationssatz daran durchführt, ob der Sender (10) Betriebsrechte
aufweist, und einen Freigabezustand des Lichtsendemoduls (13) gemäß einem Authentifizierungsergebnis
steuert;
wobei der Sender (10) ein mobiles Terminal ist und das Authentifizierungssystem ferner
einen Identifizierungscodezuteilungsserver aufweist, wobei das mobile Terminal Datenkommunikation
mit dem Identifizierungscodezuteilungsserver durch Verwendung von einem oder mehreren
Informationsnetzwerken durchführt, und der Identifizierungscodezuteilungsserver einen
eindeutigen Identifizierungscode, gemäß einer Identifizierungscodeerfassungsanfrage,
an das mit der Anfrage verbundene mobile Terminal sendet, und die Identifizierungscodeerfassungsanfrage
mit dem mobilen Terminal verbundene Information umfasst;
wobei der Identifizierungscodezuteilungsserver ein QR-Code-Erzeugungsmodul aufweist
und der Identifizierungscodezuteilungsserver einen begrenzten Verifizierungscode und
Identifizierungscode gemäß der von einem Benutzer eingegebenen Identifizierungscodeerfassungsanfrage
erzeugt und einen QR-Code des Verifizierungscodes gemäß dem Verifizierungscode durch
Verwendung des QR-Code-Erzeugungsmoduls erzeugt; das mobile Terminal ein QR-Code-Scanmodul
aufweist, und das mobile Terminal den QR-Code des Verifizierungscodes durch Verwendung
des QR-Code-Scanmoduls scannt, um den Verifizierungscode zu extrahieren, und eine
Anfrage zur Erfassung des Identifizierungscodes entsprechend dem Verifizierungscode
an den Verifizierungscodezuteilungsserver sendet, und die Identifizierungscodeerfassungsanfrage,
die von dem mobilen Terminal gesendet ist, den Verifizierungscode umfasst, der von
dem mobilen Terminal aus dem QR-Code und Identitätsinformation des mobilen Terminals
extrahiert ist, und der Identifizierungscodezuteilungsserver den Identifizierungscode,
der dem Verifizierungscode entspricht, zum mobilen Terminal sendet.
11. Verfahren zur Rechteauthentifizierung in einem Authentifizierungssystem, wobei das
Authentifizierungssystem ein Sendeterminal und ein Empfangsterminal aufweist und das
Sendeterminal einen Sender (10) aufweist, das Empfangsterminal einen Empfänger (20)
und eine Steuerung (30) aufweist, die verbunden sind, und das Verfahren umfasst:
externes Übertragen, durch den Empfänger (20), eines dem Empfänger (20) entsprechenden
erfassten Identifizierungscodeinformationssatzes; nach Empfangen des von dem Empfänger
(20) gesendeten Identifizierungscodeinformationssatzes, Durchführen einer ersten Rechteauthentifizierung
daran, ob der Sender (20) Betriebsrechte hat, durch den Sender (10) gemäß dem empfangenen
Identifizierungscodeinformationssatz, und bestimmen, ob Umwandlung von Senderinformationen
des Senders (10) in ein Lichtsignal zum Übertragen gemäß einem Authentifizierungsergebnis
zugelassen werden soll, wobei die Senderinformation (10) mindestens einen eindeutigen
Identifizierungscode eines Senders (10) umfasst; nachdem das Empfangsmodul, durch
Verwendung des Lichtempfangsmoduls (22), die Senderinformation empfangen hat, die
von dem Sender (10) in einer Lichtsignalform gesendet worden ist, Durchführen einer
zweiten Rechteauthentifizierung an der Senderinformation durch die Steuerung (30);
wobei der Sender (10) ein mobiles Terminal ist und das Authentifizierungssystem ferner
einen Identifizierungscodezuteilungsserver aufweist, das mobile Terminal Datenkommunikation
mit dem Identifizierungscodezuteilungsserver durch Verwendung von einem oder mehreren
Informationsnetzwerken durchführt und der Identifizierungscodezuteilungsserver einen
eindeutigen Identifizierungscode, gemäß einer Identifizierungscodeerfassungsanfrage,
an das mit der Anfrage verbundene mobile Terminal sendet, und die Identifizierungscodeerfassungsanfrage
mit dem mobilen Terminal verbundene Information umfasst;
wobei der Identifizierungscodezuteilungsserver ein QR-Code-Erzeugungsmodul aufweist,
und der Identifizierungscodezuteilungsserver einen begrenzten Verifizierungscode und
Identifizierungscode gemäß der von einem Benutzer eingegebenen Identifizierungscodeerfassungsanfrage
erzeugt, und einen QR-Code des Verifizierungscodes gemäß dem Verifizierungscode durch
Verwendung des QR-Code-Erzeugungsmoduls erzeugt; das mobile Terminal ein QR-Code-Scanmodul
aufweist und das mobile Terminal den QR-Code des Verifizierungscodes durch Verwendung
des QR-Code-Scanmoduls scannt, um den Verifizierungscode zu extrahieren, und eine
Anfrage zur Erfassung des Identifizierungscodes, der dem Verifizierungscode entspricht,
an den Identifizierungscodezuteilungsserver sendet und die Identifizierungscodeerfassungsanfrage,
die von dem mobilen Terminal gesendet ist, den Verifizierungscode umfasst, der von
dem mobilen Terminal aus dem QR-Code und Identitätsinformation des mobilen Terminals
extrahiert ist, und der Identifizierungscodezuteilungsserver den Identifizierungscode,
der dem Verifizierungscode entspricht, zum mobilen Terminal sendet.
12. Rechteauthentifizierungsverfahren für ein Sendeterminal, umfassend:
Empfangen eines von einem Empfänger (20) gesendeten Identifizierungscodeinformationssatzes;
Durchführen einer ersten Rechteauthentifizierung daran, ob das Sendeterminal Betriebsrechte
aufweist, gemäß dem empfangenen Identifizierungscodeinformationssatz; und
Bestimmen, ob eine Umwandlung von Senderinformation des Sendeterminals in ein Lichtsignal
zur Übertragung zugelassen werden soll gemäß einem Authentifizierungsergebnis, wobei
die Senderinformation mindestens einen eindeutigen Identifizierungscode umfasst, der
dem Sendeterminal entspricht;
wobei das Sendeterminal einen Sender (10) aufweist, der Sender (10) ein mobiles Terminal
ist, und das Authentifizierungssystem ferner einen Identifizierungscodezuteilungsserver
aufweist, wobei das mobile Terminal Datenkommunikation mit dem Identifizierungscodezuteilungsserver
durch Verwendung von einem oder mehreren Informationsnetzwerken durchführt, und der
Identifizierungscodezuteilungsserver einen eindeutigen Identifizierungscode, gemäß
einer Identifizierungscodeerfassungsanfrage, an das mit der Anfrage verbundene mobile
Terminal sendet, und die Identifizierungscodeerfassungsanfrage mit dem mobilen Terminal
verbundene Information umfasst;
wobei der Identifizierungscodezuteilungsserver ein QR-Code-Erzeugungsmodul aufweist
und der Identifizierungscodezuteilungsserver einen begrenzten Verifizierungscode und
Identifizierungscode gemäß der von einem Benutzer eingegebenen Identifizierungscodeerfassungsanfrage
erzeugt, und einen QR-Code des Verifizierungscodes gemäß dem Verifizierungscode durch
Verwendung des QR-Code-Erzeugungsmoduls erzeugt; das mobile Terminal ein QR-Code-Scanmodul
aufweist und das mobile Terminal den QR-Code des Verifizierungscodes durch Verwendung
des QR-Code-Scanmoduls scannt, um den Verifizierungscode zu extrahieren, und eine
Anfrage zur Erfassung des Identifizierungscodes, der dem Verifizierungscode entspricht,
zum Identifizierungscodezuteilungsserver sendet, und die von dem mobilen Terminal
gesendete Identifizierungscodeerfassungsanfrage den Verifizierungscode umfasst, der
von dem mobilen Terminal aus dem QR-Code und Identitätsinformationen des mobilen Terminals
extrahiert ist, und der Identifizierungscodezuteilungsserver den Identifizierungscode,
der dem Verifizierungscode entspricht, zum mobilen Terminal sendet.
13. Verfahren nach Anspruch 12, wobei der Identifizierungscodeinformationssatz eindeutige
Identifizierungscodeinformationen aller Sender umfasst, die dem Empfänger (20) entsprechen,
und Durchführen der ersten Rechteauthentifizierung daran, ob das Sendeterminal Betriebsrechte
hat, gemäß dem empfangenen Identifizierungscodeinformationssatz umfasst:
Vergleichen eines eindeutigen Identifizierungscodes des Senders (10) mit dem empfangenen
Identifizierungscodeinformationssatz durch einen Sender (10); wenn der empfangene
Identifizierungscodeinformationssatz einen Identifizierungscode umfasst, der derselbe
wie der eindeutige Identifizierungscode des Senders (10) ist, Zulassen einer Umwandlung
der Senderinformation (10) des Sendeterminals in ein Lichtsignal zum Senden durch
Verwendung eines Lichtsendemoduls (13); oder
der Identifizierungscodeinformationssatz Identitätsinformationen eines Empfangsterminals
umfasst, das Sendeterminal Identitätsinformation aller Empfangsterminals speichert,
dass das Sendeterminal Betriebsrechte hat, speichert und Durchführen der ersten Rechteauthentifizierung
daran, ob das Sendeterminal Betriebsrechte hat, gemäß dem empfangenen Identifizierungscodeinformationssatz
umfasst:
Vergleichen des empfangenen Identifizierungscodeinformationssatzes mit der Identitätsinformation
aller Empfangsterminals, dass das Sendeterminal Betriebsrechte hat, was von dem Sendeterminal
gespeichert ist, und wenn die Identitätsinformation aller empfangener Terminals, dass
das Sendeterminal die Betriebsrechte hat, was von dem Sendeterminal gespeichert ist,
den Identifizierungscodeinformationssatz umfasst, Zulassen einer Umwandlung der Senderinformation
des Sendeterminals in ein Lichtsignal zum Senden durch Verwendung eines Lichtsendemoduls
(13).
1. Un système d'authentification composé d'un terminal de transmission, d'un terminal
de réception et d'un serveur de gestion (50) et le terminal de transmission se compose
d'un transmetteur (10), alors que le terminal de réception comporte un récepteur (20)
et un contrôleur (30) et ce contrôleur (30) est raccordé, sur le plan des communications,
au récepteur (20) et au serveur de gestion (50), respectivement, et :
ce serveur de gestion (50) mémorise une série d'informations sur les codes d'identification
qui correspondent à chaque récepteur (20) ;
le récepteur (20) comporte un module de transmission d'informations (21) et un module
de réception de lumière (22) et ce module de transmission d'informations (21) et ce
module de réception de lumière (22) sont, sur le plan des communications, raccordés
au contrôleur (30), respectivement, et ce module de transmission d'informations (21)
propage, vers l'extérieur, la série acquise d'informations sur les codes d'identification
et le module de réception de lumière (22) effectue, au moins, une conversion photoélectrique
après réception d'un signal lumineux provenant du transmetteur (10) et envoie les
informations du transmetteur au contrôleur (30) ;
le contrôleur (30) effectue une deuxième authentification des droits sur les informations
du transmetteur après réception des informations du transmetteur et
le transmetteur (10) se compose d'un processeur (11), d'un module de réception d'informations
(12) et d'un module de transmission de lumière (13), et ce processeur (11) est raccordé
au module de réception d'informations (12) et au module de transmission de lumière
(13), respectivement, et ce module de réception d'informations (12) transmet la série
d'informations sur les codes d'identification au processeur (11) après réception de
la série d'informations sur les codes d'identification transmises par le module de
transmission d'informations (21) et ce processeur (11) effectue, en fonction de la
série reçue d'informations sur les codes d'identification, une première authentification
des droits pour déterminer si le transmetteur (10) a des droits opérationnels et pilote
un état d'activation du module de transmission de lumière (13) en fonction du résultat
de cette authentification et
le transmetteur (10) est un terminal mobile et ce système d'authentification comporte
en outre un serveur d'attribution de codes d'identification et ce terminal mobile
effectue une communication des données avec le serveur d'attribution de codes d'identification
en faisant appel à un ou plusieurs réseaux d'informations et ce serveur d'attribution
de codes d'identification envoie un code unique d'identification au terminal mobile
associé à la requête, en fonction d'une requête d'acquisition de code d'identification,
et cette requête d'acquisition de code d'identification contient des informations
associées à ce terminal mobile ;
et le serveur d'attribution de codes d'identification contient un module de production
de codes QR et le serveur d'attribution de codes d'identification produit un code
obligatoire de vérification et un code d'identification, en fonction de la requête
d'acquisition de code d'identification saisie par un utilisateur et produit un code
QR du code de vérification, en fonction du code de vérification, en faisant appel
au module de production de codes QR ; le terminal mobile se compose d'un module de
numérisation des codes QR et ce terminal mobile effectue un balayage du code QR du
code de vérification en faisant appel au module de numérisation des codes QR afin
d'extraire le code de vérification et envoie une requête d'acquisition du code d'identification,
qui correspond au code de vérification, au serveur d'attribution de codes d'identification
et la requête d'acquisition de code d'identification envoyée par le terminal mobile
se compose, d'une part, du code de vérification qui est extrait par le terminal mobile
à partir du code QR et, d'autre part, des informations d'identité du terminal mobile,
et le serveur d'attribution de codes d'identification envoie au terminal mobile le
code d'identification qui correspond au code de vérification.
2. Le système d'authentification que décrit la revendication 1, si ce n'est que la série
d'informations sur les codes d'identification contient des informations uniques sur
les codes d'identification de tous les transmetteurs, qui correspondent au récepteur
(20) et le processeur (11) effectue la première authentification des droits qui a
pour but de déterminer si le transmetteur (10) a des droits opérationnels, en fonction
des éléments suivants : le processeur (11) compare un code unique d'identification
du transmetteur (10) à la série d'informations reçues sur les codes d'identification
et, si la série d'informations reçues sur les codes d'identification contient un code
d'identification qui est identique au code unique d'identification du transmetteur
(10), pilote le module de transmission de lumière (13) afin de l'amener à un état
fonctionnel qui permet de convertir les informations sur le transmetteur du transmetteur
(10) en un signal lumineux en vue d'une transmission, et ces informations sur le transmetteur
contiennent, à titre minimum, le code unique d'identification du transmetteur (10).
3. Le système d'authentification que décrit la revendication 1, si ce n'est que la série
d'informations sur les codes d'identification contient des informations sur l'identité
du terminal de réception, que le transmetteur (10) mémorise les informations d'identité
de tous les terminaux de réception que le transmetteur (10) a le droit d'exploiter
et que le processeur (11) effectue la première authentification des droits afin de
déterminer si le transmetteur (10) a des droits opérationnels et cette authentification
se compose des éléments suivants : le processeur (11) compare la série reçue d'informations
sur les codes d'identification aux informations d'identité de tous les terminaux de
réception que le transmetteur (10) a le droit d'exploiter, informations qui sont mémorisées
par le transmetteur (10) et si les informations d'identité de tous les terminaux de
réception que le transmetteur (10) a le droit d'exploiter et qui sont mémorisées par
le transmetteur (10) contiennent la série d'informations sur les codes d'identification,
ordonne au module de transmission de lumière (13) de passer à un état fonctionnel
qui permet de convertir les informations sur le transmetteur (10) en un signal lumineux
de transmission, et ces informations du transmetteur contiennent, à titre minimum,
un code unique d'identification du transmetteur (10).
4. Le système d'authentification que décrit la revendication 1, si ce n'est que le module
de transmission d'informations (21) obtient directement la série d'informations sur
les codes d'identification depuis le serveur de gestion (50) et (ou) que le contrôleur
(30) obtient, du serveur de gestion (50,) une série d'informations sur les codes d'identification
qui correspondent au récepteur (20) et transmet cette série d'informations sur les
codes d'identification au module de transmission d'informations (21) du récepteur
(20).
5. Le système d'authentification que décrit la revendication 1, si ce n'est que le transmetteur
(10) comporte, en outre, un premier module de chiffrage configuré pour coder les informations
du transmetteur (10) et que ce premier module de chiffrage vient se raccorder entre
le processeur (11) et le module de transmission de lumière (13) et si ce n'est que
le récepteur (20) comporte, en outre, un deuxième module de déchiffrage et que ce
deuxième module de déchiffrage vient se raccorder entre le module de réception de
lumière (22) et le contrôleur (30) et est configuré pour assurer le décodage d'un
signal après réception d'un signal obtenu par le biais d'une conversion photoélectrique
et émis par le module de réception de lumière (22).
6. Le système d'authentification que décrit la revendication 1, si ce n'est que le récepteur
(20) comporte, en outre, un deuxième module de chiffrage et que ce deuxième module
de chiffrage vient se brancher entre le contrôleur (30) et le module de transmission
d'informations (21) et est configuré pour coder la série reçue d'informations sur
les codes d'identification en provenance du contrôleur (30) et pour envoyer la série
ainsi codée d'informations sur les codes d'identification au module de transmission
d'informations (21) ; le transmetteur (10) comporte en outre un premier module de
déchiffrage et ce premier module de déchiffrage vient se brancher entre le processeur
(11) et le module de réception d'informations (12) et est configuré pour décoder la
série d'informations sur les codes d'identification qu'a reçue le module de réception
d'informations (12) et envoie au processeur (11) cette série ainsi décodée d'informations
sur les codes d'identification.
7. Le système d'authentification que décrit la revendication 1, si ce n'est que le serveur
d'attribution de codes d'identification produit un code unique d'identification qui
correspond au numéro de terminal mobile basé sur un numéro de terminal mobile saisi
par l'utilisateur et ce terminal mobile obtient ce code d'identification à partir
du serveur d'attribution de codes d'identification en envoyant une requête d'acquisition
de code d'identification qui contient le numéro de terminal mobile.
8. Le système d'authentification que décrit la revendication 1, si ce n'est que le serveur
d'attribution de codes d'identification attribue un code d'identification à chaque
requête d'acquisition de code d'identification.
9. Le système d'authentification que décrit la revendication 1, si ce n'est que ce système
d'authentification comporte en outre un ordinateur central configuré pour produire
et supprimer un code d'identification et que le transmetteur (10) est raccordé à cet
ordinateur central en faisant appel à une ligne de données, afin d'acquérir le code
d'identification.
10. Un terminal de transmission, si ce n'est que ce terminal de transmission comporte
un transmetteur (10) et que ce transmetteur (10) comporte un processeur (11), un module
de réception d'informations (12) et un module de transmission de lumière (13) et ce
processeur (11) est raccordé, respectivement, au module de réception d'informations
(12) et au module de transmission de lumière (13), et ce module de réception d'informations
(12) transmet la série d'informations sur les codes d'identification au processeur
(11) après réception d'une série d'informations sur les codes d'identification, et
ce processeur (11) effectue une première authentification des droits pour déterminer
si le transmetteur (10) a des droits opérationnels d'après la série reçue d'informations
sur les codes d'identification et commande un état d'activation du module de transmission
de lumière (13) en fonction du résultat de cette authentification ;
si ce n'est que le transmetteur (10) est un terminal mobile et que le système d'authentification
comporte, en outre, un serveur d'attribution de codes d'identification, et ce terminal
mobile effectue une communication de données avec le serveur d'attribution de codes
d'identification en faisant appel à un ou plusieurs réseaux d'informations et le serveur
d'attribution de codes d'identification envoie un code unique d'identification au
terminal mobile associé à la requête, en fonction d'une requête d'acquisition de code
d'identification, et cette requête d'acquisition de code d'identification contient
des informations associées au terminal mobile ;
si ce n'est que le serveur d'attribution de codes d'identification comporte un module
de production de codes QR et que le serveur d'attribution de codes d'identification
produit un code obligatoire de vérification et un code d'identification, en fonction
de la requête d'acquisition de codes d'identification saisie par un utilisateur et
produit un code QR du code de vérification, en fonction du code de vérification, en
faisant appel au module de production de codes QR ; le terminal mobile se compose
d'un module de numérisation des codes QR et ce terminal mobile effectue un balayage
du code QR du code de vérification en faisant appel au module de numérisation des
codes QR afin d'extraire le code de vérification et envoie une requête d'acquisition
du code d'identification qui correspond au code de vérification au serveur d'attribution
de codes d'identification et la requête d'acquisition de code d'identification envoyée
par le terminal mobile se compose, d'une part, du code de vérification qui est extrait
par le terminal mobile à partir du code QR et, d'autre part, des informations d'identité
du terminal mobile, et le serveur d'attribution de codes d'identification envoie au
terminal mobile le code d'identification qui correspond au code de vérification.
11. Un procédé d'authentification des droits dans un système d'authentification, si ce
n'est que ce système d'authentification comporte un terminal de transmission et un
terminal de réception et que ce terminal de transmission a un transmetteur (10) alors
que ce terminal de réception a un récepteur (20) et un contrôleur (30) qui sont connectés
et ce procédé se compose des éléments suivants :
la propagation vers l'extérieur, par le récepteur (20), d'une série acquise d'informations
sur les codes d'identification qui correspond au récepteur (20) ;
après réception de la série d'informations sur les codes d'identification transmise
par le récepteur (20), l'exécution d'une première authentification des droits afin
de déterminer si le transmetteur (10) a des droits opérationnels par le transmetteur
(10), en fonction de la série reçue d'informations sur les codes d'identification,
et une détermination qui a pour but de confirmer si cela permet de convertir les informations
de transmetteur du transmetteur (10) en un signal lumineux en vue d'une transmission,
en fonction du résultat de cette authentification, et si les informations du transmetteur
(10) contiennent au moins un code unique d'identification du transmetteur (10) et
après réception par le terminal de réception, en utilisant le module de réception
de lumière (22), des informations du transmetteur qui sont transmises par le transmetteur
(10) sous la forme d'un signal lumineux, avec exécution d'une deuxième authentification
des droits sur les informations du transmetteur par le contrôleur (30) ;
si ce n'est que le transmetteur (10) est un terminal mobile et que le système d'authentification
comporte, en outre, un serveur d'attribution de codes d'identification, et ce terminal
mobile effectue une communication de données avec le serveur d'attribution de codes
d'identification en faisant appel à un ou plusieurs réseaux d'informations et le serveur
d'attribution de codes d'identification envoie un code unique d'identification au
terminal mobile associé à la requête, en fonction d'une requête d'acquisition de code
d'identification, et cette requête d'acquisition de code d'identification contient
des informations associées au terminal mobile ;
si ce n'est que le serveur d'attribution de codes d'identification comporte un module
de production de codes QR et que le serveur d'attribution de codes d'identification
produit un code obligatoire de vérification et un code d'identification, en fonction
de la requête d'acquisition de codes d'identification saisie par un utilisateur et
produit un code QR du code de vérification, en fonction du code de vérification, en
faisant appel au module de production de codes QR ; le terminal mobile se compose
d'un module de numérisation des codes QR et ce terminal mobile effectue un balayage
du code QR du code de vérification en faisant appel au module de numérisation des
codes QR afin d'extraire le code de vérification et envoie une requête d'acquisition
du code d'identification qui correspond au code de vérification au serveur d'attribution
de codes d'identification et la requête d'acquisition de code d'identification envoyée
par le terminal mobile se compose, d'une part, du code de vérification qui est extrait
par le terminal mobile à partir du code QR et, d'autre part, des informations d'identité
du terminal mobile, et le serveur d'attribution de codes d'identification envoie au
terminal mobile le code d'identification qui correspond au code de vérification.
12. Un procédé d'authentification de droits pour un terminal de transmission, composé
des éléments suivants :
réception d'une série d'informations sur les codes d'identification transmise par
un récepteur (20) ;
réalisation d'une première authentification des droits afin de déterminer si le terminal
de transmission a des droits opérationnels d'après la série reçue d'informations sur
les codes d'identification et
détermination si cela permet de convertir les informations du terminal de transmission
en un signal lumineux en vue d'une transmission, en fonction du résultat de cette
authentification, si les informations du transmetteur contiennent au moins un code
unique d'identification qui correspond au terminal de transmission ;
si ce n'est que le terminal de transmission comporte un transmetteur (10), que ce
transmetteur (10) est un terminal mobile et que le système d'authentification comporte
en outre un serveur d'attribution de codes d'identification, que ce terminal mobile
effectue une communication des données avec le serveur d'attribution de codes d'identification
en faisant appel à un ou plusieurs réseaux d'informations et que ce serveur d'attribution
de codes d'identification envoie un code unique d'identification au terminal mobile
associé à la requête, en fonction d'une requête d'acquisition de codes d'identification,
et que cette requête d'acquisition des codes d'identification contient des informations
associées à ce terminal mobile ;
si ce n'est que le serveur d'attribution de codes d'identification contient un module
de production de codes QR et que ce serveur d'attribution de codes d'identification
produit un code obligatoire de vérification et un code d'identification, en fonction
de la demande d'acquisition de codes d'identification saisie par un utilisateur et
produit un code QR du code de vérification, en fonction du code de vérification, en
faisant appel au module de production de codes QR ; que ce terminal mobile se compose
d'un module de numérisation des codes QR et que ce terminal mobile effectue un balayage
du code QR du code de vérification en faisant appel au module de numérisation des
codes QR afin d'extraire le code de vérification et envoie une requête d'acquisition
du code d'identification qui correspond au code de vérification au serveur d'attribution
de code d'identification et que la requête d'acquisition de code d'identification
envoyée par le terminal mobile se compose, d'une part, du code de vérification qui
est extrait par le terminal mobile à partir du code QR et, d'autre part, des informations
d'identité du terminal mobile, et que le serveur d'attribution de codes d'identification
envoie au terminal mobile le code d'identification qui correspond au code de vérification.
13. Le procédé que décrit la revendication 12, si ce n'est que la série d'informations
sur les codes d'identification contient des informations uniques sur les codes d'identification
de tous les transmetteurs qui correspondent au récepteur (20), et si ce n'est que
l'exécution de la première authentification des droits afin de déterminer si le terminal
de transmission a des droits opérationnels en fonction de la série reçue d'informations
sur les codes d'identification se compose des éléments suivants :
la comparaison d'un code unique d'identification du transmetteur (10) à la série reçue
d'informations sur les codes d'identification par un transmetteur (10) ;
si la série reçue d'informations sur les codes d'identification contient un code d'identification
qui est identique au code unique d'identification du transmetteur (10), ce qui permet
de convertir les informations du transmetteur (10) du terminal de transmission en
faisant appel à un module de transmission de lumière (13) ou
la série d'informations sur les codes d'identification contient des informations sur
un terminal de réception et le terminal de transmission conserve des informations
sur l'identité de tous les terminaux de réception pour lesquels le terminal de transmission
a des droits opérationnels, et l'exécution de la première authentification des droits
pour déterminer si le terminal de transmission a des droits opérationnels en fonction
de la série d'informations reçues sur les codes d'identification se compose des éléments
suivants :
la comparaison de la série reçue d'informations sur les codes d'identification aux
informations d'identité de tous les terminaux de réception que le terminal de transmission
a les droits d'exploiter et qui sont mémorisées par le terminal de transmission et
si les informations d'identité de tous les terminaux de réception que le terminal
de transmission a les droits d'exploiter et qui sont mémorisées par le terminal de
transmission contiennent la série d'informations sur les codes d'identification, ce
qui permet de convertir les informations du transmetteur du terminal de transmission
en un signal lumineux en vue d'une transmission en utilisant un module de transmission
de lumière (13).